Either you obfuscated too much or your setup makes little sense as IPA
local domain ID range is for unix.example.com while your realm is
EXAMPLE.COM and AD realm is EXAMPLE.COM. This is not going to work --
IPA and AD has to have different realms.

[root sssd]#
I see that the bind fails but I’m not sure why. Here are the errors.
Could someone point me in the right direction please?

1: NETLOGON_VERIFY_STATUS_RETURNED
pdc_connection_status : WERR_OK
trusted_dc_name : *
trusted_dc_name : '\\rh7-1.ipacloud7.test'
tc_connection_status : WERR_OK
result : WERR_OK
If instead of WERR_OK in pdc_connection_status you have something else,
that is telling an error. Show us the output like above.
--
/ Alexander Bokovoy
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project